CVE-2021-23215 PUBLISHED

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

EPSS 0.11% · 28.7th percentile

Risk Scores

EPSS Score
0.11%
28.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSopenexr0, 2.3.0-6build1, 2.3.0-6ubuntu0.5
Ubuntu:18.04:LTSopenexr2.2.0-11.1ubuntu1.1, 0, 2.2.0-11ubuntu1
Ubuntu:Pro:16.04:LTSopenexr2.2.0-7ubuntu1, 2.2.0-1ubuntu3, 2.2.0-10ubuntu2.2

Timeline

References

Open in Interactive Console →